Active Packet Analyzer for High-Speed Network Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network monitors are ineffective under high traffic conditions as they do not precisely inspect packet contents and require separate communication channels for actions, especially when devices are far apart, limiting their ability to take local actions on network traffic.

Innovation Solution

An active packet content analyzer that inspects network traffic in both directions simultaneously, using a packet processor and network search engine to normalize packets and perform actions based on predefined rules, enabling local action and communication with other network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional network monitors are used to collect information on IP packets, then network monitoring is achieved, but inspection precision deteriorates under high network traffic conditions

Engineering Contradiction:
Improvenetwork traffic handling capacityVSAvoidpacket content inspection precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The network monitor is divided into multiple specialized components: a packet processor for high-speed packet handling and normalization, a network search engine for pattern matching, and multiple communication channels for different types of information flow. This segmentation allows each component to specialize in specific tasks, maintaining inspection precision while handling high traffic volumes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A normalization layer is introduced as an intermediary between packet capture and analysis. The packet processor normalizes incoming packets into a standardized format before they reach the analysis components, enabling efficient processing without sacrificing inspection precision even under high traffic conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional network monitors use separate communication channels for actions, then communication with remote devices is achieved, but response time deteriorates when devices are located far away

Engineering Contradiction:
Improvecommunication capability with remote devicesVSAvoidresponse time for taking actions on packets
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

Multiple communication channels are merged into a unified communication interface that can handle both monitoring data and control actions simultaneously. This integration allows the system to send alerts and receive control commands through the same high-speed interface, eliminating the time delay associated with separate communication channels and enabling rapid response even for remote devices.

Inventive Principle:
Principle #5Merging (Combining)

3Extent of automation

If conventional network monitors passively collect information, then network traffic monitoring is achieved, but the ability to take local actions on network traffic deteriorates

Engineering Contradiction:
Improveautomated information collectionVSAvoidability to take local actions on packets
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system transitions from a static passive monitoring mode to a dynamic active monitoring mode. The unified communication interface can dynamically switch between receiving monitoring data and sending control actions, and the system can automatically execute predefined actions (such as blocking malicious packets) without requiring constant external intervention, thereby enabling effective local actions on network traffic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A feedback mechanism is implemented where the system not only collects information about network packets but also automatically responds to detected threats by executing predefined actions. The unified communication interface provides feedback loops that allow the system to adjust its behavior based on real-time network conditions, enabling automated local actions such as blocking suspicious traffic or alerting security systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP1908219B1Active packet content analyzer for communications network
Publication Date: 2018.03.21 KEYSIGHT TECH SINGAPORE HLDG
  • EP1908219B1 patent drawingFigure 1
  • EP1908219B1 patent drawingFigure 2A
  • EP1908219B1 patent drawingFigure 2B

AI summary

An active packet inspection device for a communications network, comprises a first terminal and a second terminal each adapted to couple the appliance in-line in the network and communicate data packets with network devices. A packet processor is coupled to the first terminal and second terminal and configured to normalize the data packets. A network search engine coupled to the packet processor and the memory, and configured to compare the data packets with the stored signatures, and when a match is found and other specified conditions are met, to perform an action identified in an associated rule. In one aspect, the network search engine includes a network search engine controller and a network search engine table including a memory configured to store a plurality of replicated signatures. Advantages of the invention include the ability to perform deep packet inspections actively on a communications network at high-speed.